Back to Hype Deals

Privacy Policy

Privacy Policy

Last updated: 12 June 2026

Hype Deals UK ("we", "our", or "us") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our website, in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Please read this policy carefully to understand our practices regarding your personal data. Where we rely on your consent (for example, analytics or marketing cookies), we will always ask for it separately and you can withdraw it at any time. Your use of our services is also governed by our Terms of Service, which set out the contractual basis for processing your data when you publish content on the platform.

Contents

  1. 1.Who We Are (Controller Information)
  2. 2.Personal Data We Collect
  3. 3.How We Collect Your Data
  4. 4.Why We Process Your Data (Legal Basis)
  5. 5.How We Use Your Data
  6. 6.Data Sharing & Third-Party Processors
  7. 7.International Data Transfers
  8. 8.Data Retention
  9. 9.Your Rights Under UK GDPR
  10. 10.Cookie Policy
  11. 11.Data Security
  12. 12.Children's Privacy
  13. 13.Changes to This Policy
  14. 14.How to Contact Us
  15. 15.Right to Complain

1. Who We Are (Controller Information)

For the purposes of the UK GDPR, the data controller is:

Controller:
Hype Deals UK (sole trader)
Registered:
United Kingdom
Website:
Hype Deals UK deals website
Contact:
You can contact us via the website or through our data protection contact form.

2. Personal Data We Collect

We collect the following categories of personal data:

Account Data

Google (via OAuth)

Email address, full name, and avatar URL provided by Google OAuth when you sign in.

Profile Data

Directly from you

Nickname (chosen by you), selected avatar (SVG or uploaded image), and onboarding status.

Activity Data

Directly from you

Your votes on deals (upvote/downvote) and any comments you submit.

Uploaded Content

Directly from you

Custom avatar images (JPG/PNG, max 200KB) uploaded to our storage.

Personalization Data

Directly from you (opt-in)

Your selected interest categories and keywords (optional). Used only when you opt-in to personalized recommendations. You can withdraw consent and delete this data anytime.

Consent Records

Directly from you

Your cookie consent preferences, personalization consent status, consent version, timestamp, and session identifier.

Recommendation Logs

Automatically

Anonymized record of deals you're recommended (no personal identifiers, expires after 90 days). Used to improve recommendation quality.

Technical Data

Automatically

IP address (hashed via SHA-256, never stored raw), browser user agent, and device type.

Usage Data

Google Analytics (with consent)

Pages visited, time spent on site, and interaction patterns (only when you consent to analytics cookies).

3. How We Collect Your Data

We collect personal data through the following methods:

  • •Direct interaction: When you sign in with Google OAuth, complete the onboarding form, update your profile, vote on deals, or submit comments.
  • •Automated technologies: When you interact with our website, we may automatically collect technical data about your device and browsing actions via cookies (only with your consent for non-essential cookies).
  • •Third parties: We receive your email, name, and avatar URL from Google when you authenticate via Google OAuth.

4. Why We Process Your Data (Legal Basis)

Under UK GDPR, we must have a lawful basis for processing your personal data. Our legal bases are:

Consent (Article 6(1)(a))

Analytics cookies, marketing/tracking cookies, and any optional data processing.

You can withdraw consent at any time via the cookie banner or by contacting us.

Contract (Article 6(1)(b))

Processing necessary to provide our services — managing your user account, profile, votes, and comments.

Without this data, we cannot provide the Hype Deals community features.

Legitimate Interests (Article 6(1)(f))

Rate limiting to prevent abuse, security monitoring, and improving our services.

Our legitimate interests do not override your fundamental rights and freedoms.

Legal Obligation (Article 6(1)(c))

Compliance with UK laws, including tax, consumer protection, and data protection regulations.

We may be required to retain certain data for legal compliance purposes.

5. How We Use Your Data

  • •To create and manage your user account (email, name, avatar).
  • •To display your nickname and avatar on comments and votes.
  • •To record and display your votes on deals.
  • •To store and display your comments on deals.
  • •To personalise your experience (theme preferences, saved settings).
  • •To analyse site usage and improve our services (with your consent).
  • •To track affiliate link clicks for revenue generation (with your consent).
  • •To prevent abuse and ensure site security (rate limiting, session management).

6. Data Sharing & Third-Party Processors

We share your personal data with the following third-party service providers, all of whom act as data processors on our behalf and are bound by data processing agreements:

ProcessorPurposeData SharedLocation
SupabaseAuthentication, database, file storageEmail, name, profile data, votes, comments, avatarsUSA (EU-US DPF)
Google (OAuth)User authenticationEmail, name, avatar URLUSA (EU-US DPF)
Google AnalyticsSite analytics (with consent only)Page views, anonymised IP, usage patternsUSA (EU-US DPF)
CloudinaryImage hosting and CDN for deal imagesProduct images (no personal data)USA (EU-US DPF)
Amazon AssociatesAffiliate link tracking (with consent only)Click data via affiliate tag in URLsUSA (EU-US DPF)

All US-based processors are covered under the EU-US Data Privacy Framework (DPF) or appropriate Standard Contractual Clauses (SCCs). We do not sell your personal data to any third party.

7. International Data Transfers

Some of our service providers are located outside the United Kingdom, including in the United States. Where this is the case, we ensure your data is protected by one of the following mechanisms:

  • •Adequacy decisions: The European Commission has determined that the EU-US Data Privacy Framework provides adequate protection.
  • •Standard Contractual Clauses (SCCs): Where no adequacy decision exists, we use SCCs approved by the UK ICO.
  • •Data Processing Agreements: All processors are bound by agreements requiring them to protect your data in line with UK GDPR standards.

8. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:

Account data (email, name, profile)
Until you delete your account or request erasure
Votes and comments
Until you delete your account (cascade deletion)
Uploaded avatars
Until you delete your account or upload a replacement
Cookie consent records
24 months from the date of consent
Rate limiting data (IP addresses)
In-memory only, cleared on server restart (typically within minutes)
Analytics data (Google Analytics)
14 months (Google's default retention period)

9. Your Rights Under UK GDPR

Under the UK GDPR, you have the following rights in relation to your personal data. You can exercise these rights at any time by contacting us or using the features built into your account settings:

Right of Access (Article 15)

You can request a copy of all personal data we hold about you. Use the "Export My Data" feature in your account settings to download your data in JSON format.

Right to Rectification (Article 16)

You can update or correct your personal data at any time via your account settings (nickname, avatar). For other corrections, contact us directly.

Right to Erasure (Article 17)

You can request deletion of your account and all associated data via the "Delete My Account" feature in Settings > Danger Zone. This will permanently remove your profile, votes, comments, and uploaded avatars.

Right to Restrict Processing (Article 18)

You can restrict how we process your data by adjusting your cookie preferences or contacting us to request processing restrictions.

Right to Data Portability (Article 20)

You can download your personal data in a structured, machine-readable JSON format via the "Export My Data" feature in your account settings.

Right to Object (Article 21)

You can object to processing based on legitimate interests (e.g., analytics, marketing) by rejecting non-essential cookies in the cookie banner or adjusting your preferences at any time.

Right to Withdraw Consent (Article 7(3))

Where processing is based on consent (analytics, marketing cookies), you can withdraw consent at any time via the cookie banner. Withdrawal does not affect the lawfulness of processing before withdrawal.

We will respond to any valid request within one month. For complex requests, this may be extended by two further months, in which case we will inform you of the delay.

10. Cookie Policy

We use cookies and similar technologies to provide and improve our services. When you first visit our website, you will see a cookie consent banner where you can choose which types of cookies to allow.

Strictly Necessary

Always enabled

Essential for the website to function (e.g., sign-in sessions, security, remembering your cookie choices). Cannot be disabled.

Examples: Supabase authentication cookies, admin session cookie, cookie consent record

Functional

Disabled by default (requires consent)

Remember your preferences, theme settings, and saved configurations.

Examples: Theme preference

Analytics

Disabled by default (requires consent)

Help us understand how visitors interact with the site to improve our services.

Examples: Google Analytics (gtag.js) — page views, anonymised IP addresses

Marketing

Disabled by default (requires consent)

Used to deliver relevant advertisements and track affiliate link clicks.

Examples: Amazon Associates affiliate tag in outbound URLs

You can change your cookie preferences at any time by clicking the cookie icon in the bottom corner of the website or by clearing your browser cookies. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:

  • •HTTPS/TLS encryption for all data in transit.
  • •HttpOnly, Secure, and SameSite cookies for session management.
  • •Row Level Security (RLS) in our database to ensure users can only access their own data.
  • •Rate limiting to prevent brute-force attacks and abuse.
  • •Input sanitisation to prevent cross-site scripting (XSS) attacks.
  • •Restricted access to admin functions via password-protected sessions.
  • •Regular security reviews and updates to our infrastructure.

12. Children's Privacy

Our website is not intended for children under the age of 13. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will take steps to delete such information.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by updating the "Last updated" date at the top of this policy. We encourage you to review this policy periodically.

14. How to Contact Us

If you have any questions about this Privacy Policy or our data practices, or if you wish to exercise any of your rights, please contact us:

General enquiries:
Via the Hype Deals UK website
Data protection enquiries:
Contact us through the website with the subject line "Data Protection Request"
Response time:
We aim to respond within one month of receiving your request.

15. Right to Complain

You have the right to lodge a complaint with a supervisory authority if you believe your personal data has been processed in a way that infringes the UK GDPR.

Information Commissioner's Office (ICO)

The ICO is the UK's independent supervisory authority for data protection.

Website: ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would appreciate the opportunity to address your concerns before you contact the ICO. Please contact us first so we can try to resolve any issues.

Hype Deals UK Privacy Policy — Compliant with UK GDPR and Data Protection Act 2018